Company
FinTech
Sr.CyberSecurityAnalyst
Neural analysis suggests this role is
optimal for Senior candidates.
“Sr. Cyber Security Analyst. Skills: Cybersecurity, GRC, Risk management, Compliance. Support third-party audits. Coordinate third-party audits”
Industry & Context.
What They're Looking For.
Must Have
3-5 years cybersecurity experience, 3-5 years IT risk experience, 3-5 years GRC experience, Understanding compliance frameworks, Hands-on audit support, Hands-on certification support, Hands-on regulatory assessment support, Knowledge of risk management, Knowledge of control design, Knowledge of compliance documentation, Experience handling security questionnaires, Translate technical controls, Familiarity with IAM, Familiarity with access governance
Nice to Have
GRC platforms experience, SaaS environment exposure, FinTech environment exposure, Regulated environment exposure, CISA certification preferred, ISO 27001 Lead Auditor preferred, ISO 27001 Implementer preferred, PCI ISA certification preferred
What You'll Do.
Support third-party audits
Coordinate third-party audits
Support certifications
Coordinate certifications
Support regulatory assessments
Coordinate regulatory assessments
Maintain GRC framework
Enhance GRC framework
Develop security policies
Review security policies
Update security policies
Develop security standards
Review security standards
Update security standards
Develop security controls
Review security controls
Update security controls
Manage security questionnaires
Manage customer due diligence
Conduct vendor risk assessments
Track third-party compliance
Maintain risk registers
Maintain mitigation plans
Perform enterprise-wide risk assessments
Document risk assessments
Track risk remediation
Support access governance
Conduct access reviews
Manage identity lifecycle
Enforce least privilege
Contribute to incident response
Contribute to disaster recovery
Contribute to security awareness
Monitor evolving threats
Monitor compliance requirements
Monitor industry best practices
Strengthen security posture
How You'll Work.
Team & Collaboration
Collaborative work culture; Involving security teams; Involving engineering teams; Involving legal teams; Involving product teams
Communication Scope
Stakeholder coordination
Full Job Description
## Accountabilities Support the execution and coordination of third-party audits and certifications, including SOC 2, PCI-DSS, ISO 27001, and NIST CSF. Maintain and enhance the organization’s GRC framework by developing, reviewing, and updating security policies, standards, and controls. Manage security questionnaires and customer due diligence requests, ensuring accurate and timely responses. Conduct vendor risk assessments, track third-party compliance, and maintain risk registers and mitigation plans. Perform enterprise-wide risk assessments across systems, processes, and tools, ensuring proper documentation and remediation tracking. Support access governance activities, including periodic access reviews, identity lifecycle management, and least privilege enforcement. Contribute to incident response planning, disaster recovery readiness, and security awareness initiatives. Monitor evolving threats, compliance requirements, and industry best practices to continuously strengthen the security posture. Requirements: 3–5 years of experience in cybersecurity, IT risk, or GRC-focused roles. Strong understanding of compliance frameworks such as SOC 2, ISO 27001, PCI-DSS, and NIST CSF. Hands-on experience supporting audits, certifications, or regulatory assessments. Knowledge of risk management methodologies, control design, and compliance documentation practices. Experience handling security questionnaires and translating technical controls for business stakeholders. Familiarity with identity and access management (IAM) and access governance processes. Strong communication, documentation, and stakeholder coordination skills. Experience with GRC platforms such as Vanta, Drata, or similar tools is a plus. Exposure to SaaS, FinTech, or regulated environments is highly desirable. Certifications such as CISA, ISO 27001 Lead Auditor/Implementer, or PCI ISA are preferred but not mandatory. Benefits: Opportunity to work in a high-impact cybersecurity and compliance function with
Applying for this Sr. Cyber Security Analyst role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Lever
- Lever uses a streamlined one-page form — apply in under 5 minutes.
- LinkedIn import works well; review parsed data before submitting.
- The cover letter field is optional but visible to reviewers — use it to differentiate.
- Referral codes from employees can significantly boost visibility of your application.
ANONYMOUS · UNFILTERED
What do employees actually say about this company?
Real rants from real employees. Read before you apply.